Fino

Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) · 3 December 2020

Karolinska University Hospital of Solna

Insufficient technical and organisational measures to ensure information security

Fine€390,100Fine issued
Regulator
Data Protection Authority of Sweden (Integritetsskyddsmyndigheten)
Decided
3 December 2020
Country
Sweden
Sector
Health Care
Regulator’s reference
Not recorded
Fino case number
2020/SE/004
Export as PDF

What happened

The Swedish DPA (Datainspektionen) held that access to medical records has to be restricted based on the individual care workers’ necessity to perform his/her job. The DPA therefore fined the Karolinska University Hospital approximately €391,000 for violating Articles 5 and 32 GDPR.

Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles
  • Data security

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/SE/004.